CVE-2016-3084
published 2022-05-13CVE-2016-3084: CVE-2016-3084 [HIGH] Cloud Foundry UAA reset password vulnerable to brute force attack Cloud Foundry UAA reset password vulnerable to brute force attack The…
PriorityP344high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
1.19%
64.1th percentile
CVE-2016-3084 [HIGH] Cloud Foundry UAA reset password vulnerable to brute force attack
Cloud Foundry UAA reset password vulnerable to brute force attack
The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal Elastic Runtime versions prior to 1.7.2 is vulnerable to a brute force attack due to multiple active codes at a given time. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cloud Foundry UAA reset password vulnerable to brute force attack
ghsa·2022-05-13
CVE-2016-3084 [HIGH] Cloud Foundry UAA reset password vulnerable to brute force attack
Cloud Foundry UAA reset password vulnerable to brute force attack
The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal Elastic Runtime versions prior to 1.7.2 is vulnerable to a brute force attack due to multiple active codes at a given time. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.
OSV
linux-lts-xenial vulnerabilities
osv·2016-09-19·CVSS 6.5
CVE-2016-6136 linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3084-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller dev
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-13
Published